CFS Cheat Sheet 2026

The 30 highest-yield CFS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
180 min time limit
75% to pass
  1. A company requires that journal entries above $10,000 be approved by the CFO. This control is best classified as: → Preventive control
  2. Multi-factor authentication (MFA) reduces identity theft risk primarily by: → Requiring attackers to compromise multiple independent verification factors
  3. Which control is most effective at preventing a single employee from executing a billing scheme undetected? → Segregating duties so that no single employee can both add vendors and approve payments
  4. In a jury trial, the fraud examiner is presenting a chart showing a complex embezzlement scheme. The most effective presentation technique is to: → Build the chart incrementally, explaining each layer before adding the next
  5. In a lapping scheme, a fraudster covers a misappropriated payment from Customer A by applying a later payment from which source? → Customer B's subsequent payment
  6. Which regulatory body oversees securities markets in the U.S.? → Securities and Exchange Commission (SEC).
  7. A fraud examiner is testifying about a Ponzi scheme. The most persuasive way to explain the scheme's mechanics to jurors is to: → Use a simple visual showing money flowing from new investors to pay old investors
  8. Healthcare fraud committed by a provider billing Medicare for services never rendered is an example of: → Phantom billing
  9. In digital forensics, 'write blockers' are used to: → Prevent any writes to the evidence drive during acquisition, preserving its integrity
  10. Which indicator is a classic red flag for a billing scheme involving fictitious vendors? → Vendors with physical addresses matching employee addresses
  11. A 'lapping' scheme is most likely to be detected by: → Comparing customer account balances to statements and confirming directly with customers
  12. A company implements mandatory job rotation for employees who handle cash. This control primarily addresses which fraud risk factor? → Opportunity
  13. Which governance practice helps prevent a single individual from committing and concealing fraud? → Job rotation and mandatory vacations
  14. Check kiting exploits which banking vulnerability? → The float period between check deposit and fund clearance
  15. According to ACFE research, what is the most common initial detection method for occupational fraud, including asset misappropriation? → A tip from an employee or other informant
  16. Which technique is most effective in preventing fraudulent financial reporting? → Implementing strong corporate governance and oversight.
  17. Under SOX Section 404, management is required to: → Assess and report on the effectiveness of internal controls over financial reporting
  18. The COSO framework's control environment component most directly supports fraud prevention by: → Establishing the ethical foundation and governance structures of the organization
  19. What is a key principle of witness interviewing techniques in Certified Fraud Specialist practice? → Applying structured methodologies based on evidence and best practices
  20. Which concept describes the risk that remains after management has implemented controls to reduce inherent risk? → Residual risk
  21. Management override of internal controls is considered particularly dangerous because: → Controls cannot detect or prevent actions by those who designed them
  22. A ghost employee scheme is most effectively prevented by which control? → Periodic physical verification of employees matched to payroll records
  23. Which fraud risk is heightened when a company has a dominant CEO who overrides controls without challenge? → Management override
  24. Which quantitative method is used to estimate the expected loss from a fraud risk by combining its likelihood and impact? → Expected value calculation (probability × impact)
  25. Which analytical technique flags transactions that fall just below an approval threshold repeatedly? → Threshold circumvention detection
  26. What is the primary purpose of a hotline as an anti-fraud control? → Provide anonymous tips about suspected misconduct
  27. Continuous monitoring differs from periodic auditing primarily because it: → Detects anomalies in real time as transactions occur
  28. The term 'spoliation of evidence' in a fraud investigation refers to: → The intentional or negligent destruction, alteration, or concealment of evidence
  29. When implementing expert testimony & court presentation practices, what should CFS professionals prioritize? → Alignment with professional standards, stakeholder needs, and organizational goals
  30. What is a key principle of insurance fraud investigation in Certified Fraud Specialist practice? → Applying structured methodologies based on evidence and best practices
Turn these facts into recall:
Was this helpful?